Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\aloyyadi
*******************
Script file located at: \??\C:\Program Files\fcgpiwhx.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Driver wfmtvbdq unloaded successfully.
File c:\windows\system32\drivers\uqaadtgx.sys not found!
Deletion of file c:\windows\system32\drivers\uqaadtgx.sys failed!
Could not process line:
c:\windows\system32\drivers\uqaadtgx.sys
Status: 0xc0000034
Error: C:\WINDOWS\System32\o is not a folder! It may instead be a file.
Deletion of folder C:\WINDOWS\System32\o failed!
Could not process line:
C:\WINDOWS\System32\o
Status: 0xc0000103
Completed script processing.
*******************
Finished! Terminate.
"aaaa" - 2007-07-13 19:09:53 - ComboFix 07-07-04.4 FAT32
((((((((((((((((((((((((( Files Created from 2007-06-13 to 2007-07-13 )))))))))))))))))))))))))))))))
2007-07-12 22:59 <DIR> d-------- C:\Deckard
2007-07-12 18:50 <DIR> d--hs---- C:\FOUND.002
2007-07-11 22:34 <DIR> d-------- C:\Program Files\NAPI-PROJEKT
2007-07-11 12:57 86,016 -ra------ C:\WINDOWS\system32\ZSPOOL.DLL
2007-07-11 12:57 86,016 -ra------ C:\WINDOWS\system32\ZLhp1020.dll
2007-07-11 12:57 28,672 -ra------ C:\WINDOWS\system32\zlm.dll
2007-07-11 12:57 28,672 -ra------ C:\WINDOWS\system32\IMF32.DLL
2007-07-11 12:57 24,576 -ra------ C:\WINDOWS\system32\ZTAG32.DLL
2007-07-11 12:57 143,360 -ra------ C:\WINDOWS\apptune1020.exe
2007-07-11 12:57 106,496 -ra------ C:\WINDOWS\system32\vshp1020.dll
2007-07-11 12:57 1,175,552 -ra------ C:\WINDOWS\system32\zshp1020.exe
2007-07-11 12:57 <DIR> d--h----- C:\Program Files\Zenographics
2007-07-11 12:57 <DIR> d-------- C:\Program Files\Hewlett-Packard
2007-07-11 12:55 <DIR> d-------- C:\DOCUME~1\aaaa\DANEAP~1\AdobeUM
2007-07-11 12:49 <DIR> d-------- C:\WINDOWS\Cache
2007-07-06 23:10 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-07-06 22:10 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-06 20:45 <DIR> d--hs---- C:\FOUND.001
2007-07-06 20:32 <DIR> d--hs---- C:\FOUND.000
2007-07-06 20:20 545 --a------ C:\WINDOWS\UC.PIF
2007-07-06 20:20 545 --a------ C:\WINDOWS\RAR.PIF
2007-07-06 20:20 545 --a------ C:\WINDOWS\PKZIP.PIF
2007-07-06 20:20 545 --a------ C:\WINDOWS\PKUNZIP.PIF
2007-07-06 20:20 545 --a------ C:\WINDOWS\NOCLOSE.PIF
2007-07-06 20:20 545 --a------ C:\WINDOWS\LHA.PIF
2007-07-06 20:20 545 --a------ C:\WINDOWS\ARJ.PIF
2007-07-06 20:20 <DIR> d-------- C:\totalcmd
2007-07-06 20:19 <DIR> d-------- C:\Program Files\DivX Subtitle Displayer
2007-07-06 20:18 <DIR> d-------- C:\Program Files\The Playa
2007-07-06 20:18 <DIR> d-------- C:\Program Files\DivXCodec
2007-07-06 20:17 <DIR> d-------- C:\Program Files\ffdshow
2007-07-05 23:38 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Windows Genuine Advantage
2007-07-05 23:10 975 --a------ C:\WINDOWS\mozver.dat
2007-07-05 23:10 4 --a------ C:\WINDOWS\system32\proc97.bin
2007-07-05 23:10 <DIR> d-------- C:\DOCUME~1\aaaa\DANEAP~1\GanymedeNet
2007-07-05 23:04 0 --a------ C:\WINDOWS\nsreg.dat
2007-07-05 20:14 977,920 --a------ C:\WINDOWS\system32\msdtctm.dll
2007-07-05 20:14 64,512 --a------ C:\WINDOWS\system32\mtxclu.dll
2007-07-05 20:14 64,512 --a------ C:\WINDOWS\system32\colbact.dll
2007-07-05 20:14 499,200 --a------ C:\WINDOWS\system32\comuid.dll
2007-07-05 20:14 365,568 --a------ C:\WINDOWS\system32\msdtcprx.dll
2007-07-05 20:14 226,816 --a------ C:\WINDOWS\system32\es.dll
2007-07-05 20:14 150,528 --a------ C:\WINDOWS\system32\msdtcuiu.dll
2007-07-05 20:14 110,080 --a------ C:\WINDOWS\system32\clbcatex.dll
2007-07-05 20:13 97,280 --a------ C:\WINDOWS\system32\txflog.dll
2007-07-05 20:13 82,432 --a------ C:\WINDOWS\system32\mtxoci.dll
2007-07-05 20:13 596,480 --a------ C:\WINDOWS\system32\catsrvut.dll
2007-07-05 20:13 593,408 --a------ C:\WINDOWS\system32\h323msp.dll
2007-07-05 20:13 552,448 --a------ C:\WINDOWS\system32\rtcdll.dll
2007-07-05 20:13 48,640 --a------ C:\WINDOWS\system32\browser.dll
2007-07-05 20:13 454,144 --a------ C:\WINDOWS\system32\ipnathlp.dll
2007-07-05 20:13 442,880 --a------ C:\WINDOWS\system32\rpcrt4.dll
2007-07-05 20:13 36,864 --a------ C:\WINDOWS\system32\mf3216.dll
2007-07-05 20:13 225,280 --a------ C:\WINDOWS\system32\catsrv.dll
2007-07-05 20:13 214,528 --a------ C:\WINDOWS\system32\rpcss.dll
2007-07-05 20:13 1,177,088 --a------ C:\WINDOWS\system32\comsvcs.dll
2007-07-05 20:13 1,105,408 --a------ C:\WINDOWS\system32\ole32.dll
2007-07-05 18:43 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-07-05 18:43 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Dane aplikacji
2007-07-05 18:43 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Menu Start
2007-07-05 18:43 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Ustawienia lokalne
2007-07-05 18:43 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Szablony
2007-07-05 18:43 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Ulubione
2007-07-05 18:43 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Pulpit
2007-07-05 18:43 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Moje dokumenty
2007-07-05 06:55 7,680 --------- C:\WINDOWS\system32\bitsprx2.dll
2007-07-05 06:55 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll
2007-07-05 06:55 331,776 --a------ C:\WINDOWS\system32\winhttp.dll
2007-07-05 06:55 17,408 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2007-07-05 06:55 <DIR> d-------- C:\WINDOWS\system32\bits
2007-07-04 00:15 26,112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe
2007-07-04 00:15 <DIR> d--h----- C:\WINDOWS\$xpsp1hfm$
2007-07-04 00:07 <DIR> d-------- C:\WINDOWS\pss
2007-07-03 22:55 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-03 22:55 33,624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-03 22:55 325,976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-03 22:54 549,720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-03 22:54 <DIR> d-------- C:\WINDOWS\SoftwareDistribution
2007-07-03 22:53 <DIR> d---s---- C:\DOCUME~1\aaaa\UserData
2007-07-03 21:31 <DIR> d-------- C:\WINDOWS\system32\ildewo
2007-07-03 18:28 20,016 --------- C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-07-03 18:28 <DIR> d-------- C:\Program Files\Winamp
2007-07-02 19:51 <DIR> d--hs---- C:\Recycled
2007-07-01 22:34 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-07-01 21:38 <DIR> d-------- C:\DOCUME~1\aaaa\DANEAP~1\Help
2007-07-01 18:17 502,368 --a------ C:\WINDOWS\system32\drivers\amon.sys
2007-07-01 18:17 274,432 --a------ C:\WINDOWS\system32\imon.dll
2007-07-01 18:14 <DIR> d-------- C:\Program Files\Gadu-Gadu
2007-07-01 18:14 <DIR> d-------- C:\DOCUME~1\aaaa\Gadu-Gadu
2007-07-01 18:10 <DIR> d--hs---- C:\WINDOWS\Installer
2007-07-01 18:09 1,310,720 --ah----- C:\DOCUME~1\aaaa\NTUSER.DAT
2007-07-01 18:09 <DIR> dr-h----- C:\DOCUME~1\aaaa\Dane aplikacji
2007-07-01 18:09 <DIR> dr------- C:\DOCUME~1\aaaa\Ulubione
2007-07-01 18:09 <DIR> dr------- C:\DOCUME~1\aaaa\Moje dokumenty
2007-07-01 18:09 <DIR> dr------- C:\DOCUME~1\aaaa\Menu Start
2007-07-01 18:09 <DIR> d--h----- C:\DOCUME~1\aaaa\Ustawienia lokalne
2007-07-01 18:09 <DIR> d--h----- C:\DOCUME~1\aaaa\Szablony
2007-07-01 18:09 <DIR> d-------- C:\DOCUME~1\aaaa\Pulpit
2007-07-01 17:49 241,664 --ah----- C:\DOCUME~1\NETWOR~1\NTUSER.DAT
2007-07-01 17:49 241,664 --ah----- C:\DOCUME~1\LOCALS~1\NTUSER.DAT
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-06 23:39:06 49,492 ----a-w C:\WINDOWS\system32\perfc015.dat
2007-07-06 23:39:06 355,486 ----a-w C:\WINDOWS\system32\perfh015.dat
2007-07-01 15:31:32 -------- d-----w C:\Program Files\Usługi online
2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 20:43:44 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 20:43:40 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2003-05-12 00:47 50376 --a------ C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-07-01 18:16]
"OrderReminder"="C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 13:18]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msennger]
C:\WINDOWS\System32\ildewo\york.exe
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}
rundll32 iesetup.dll,IEAccessUserInst
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-13 19:11:19
Windows 5.1.2600 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-13 19:12:08
--- E O F ---
[/code]
[ Dodano: Dzisiaj o 18:21 ] co do przeskanowanego pliku wszystko ok. nie ma wirusa.
Pozdrawiam i dzieki z góry za pomoc:))